Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Winfixer?!


  • This topic is locked This topic is locked

#1
Invisible Touch

Invisible Touch

    Member

  • Member
  • PipPip
  • 14 posts
ive been having problem with a pop-up called winfixer that every time i go to a website it prompts me to download software. no matter what i click it redirects me to the winfixer website. i dont know what is the source of this problem and i hope someone could help me find out what is. thanks

Hi Jack This log:

Logfile of HijackThis v1.99.1
Scan saved at 5:57:09 PM, on 8/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\QW5keQAA\command.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\etb\pokapoka63.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\j?vaw.exe
C:\Program Files\ornu\nslo.exe
C:\Program Files\America Online 9.0a\aoltray.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Ed\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.limewire.com/clientpro?en
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\system32\exp.exe
O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka63.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\system32\sfg.dll"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [System service63] C:\WINDOWS\etb\pokapoka63.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [WinFixer 2005] C:\Program Files\WinFixer 2005\wfx5.exe
O4 - HKLM\..\Run: [second] C:\Documents and Settings\Ed\Desktop\l2mfix\second.bat
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Onu] C:\WINDOWS\system32\j?vaw.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\system32\sfg.dll"
O4 - HKCU\..\Run: [Srro] C:\Program Files\ornu\nslo.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0a\aoltray.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O15 - Trusted Zone: http://www.newgrounds.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/...ner/WFXScan.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\QW5keQAA\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

Advertisements


#2
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
Welcome Invisible Touch to Geeks to Go!

I see you started working on fixing it yourself. Please wait for an advise.

We need to disable your Microsoft AntiSpyware Real-time Protection as it may interfere with the fixes that we need to make.

Open Microsoft AntiSpyware.
Click on Tools, Settings.
In the left pane, click on Real-time Protection.
Under Startup Options uncheck Enable the Microsoft AntiSpyware Security Agents on startup (recommended).
Under Real-time spyware threat protection uncheck Enable real-time spyware threat protection (recommended).
After you uncheck these, click on the Save button and close Microsoft AntiSpyware.
Right click on the Microsoft AntiSpyware icon on the taskbar and select Shutdown Microsoft AntiSpyware.
Reverse the process when you’ve carried out the advise.

***

Go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called:

Command Service

When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.

***

Open HijackThis
click on "None of the above, just start the program".
click on the "Config" button (bottom right),
click on "Misc Tools"
click on "Delete an NT Service" (a window will pop up)
Enter the below item into that field (make sure there are NO spaces before or after the name):

cmdService

Click OK.

It should pull up information about the service, then ask if you want to reboot. Click YES.

***

Please download, install, and update the free version of Ewido trojan scanner:
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Run Ewido --- When you run it for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • From the main ewido screen, click on update in the left menu, then click the Start update button.
  • After the update finishes (the status bar at the bottom will display "Update successful")
  • Exit Ewido. DO NOT scan yet.
***

Download LQfix by Miekiemoes.
Unzip it to your desktop.
Don't use it yet.

***

Download the Killbox.
Unzip it to the desktop

Double-click on Killbox.exe to run it. Place the following lines (complete paths) in bold in the "Full Path of File to Delete" box in Killbox, and click the red button with the white X on it after each

C:\WINDOWS\system32\exp.exe
C:\WINDOWS\system32\sfg.dll
C:\Program Files\WinFixer 2005\wfx5.exe
C:\Program Files\ornu\nslo.exe
C:\WINDOWS\QW5keQAA\command.exe

For these file, put a mark next to "Delete on Reboot". Copy and paste each file into the file name box, then click the red button with the X after each. It will ask you if you want to reboot each time you click it, answer NO until after you've pasted the last file name, at which time you should answer Yes.
Click "No" at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually.

***

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.co.../safemode.shtml

***

Run LQfix.

***

Open HijackThis
Place a check against each of the following, making sure you get them all and not any others by mistake:

R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\system32\exp.exe

O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\system32\sfg.dll"

O4 - HKLM\..\Run: [WinFixer 2005] C:\Program Files\WinFixer 2005\wfx5.exe

O4 - HKCU\..\Run: [Onu] C:\WINDOWS\system32\j?vaw.exe

O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\system32\sfg.dll"

O4 - HKCU\..\Run: [Srro] C:\Program Files\ornu\nslo.exe

O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/...ner/WFXScan.cab

Close all programs leaving only HijackThis running.
Click on Fix Checked when finished and exit HijackThis.

***

Next, run Ewido again.
  • Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
  • If ewido finds anything, it will pop up a notification. We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, pcAnywhere and the game "Risk" have been flagged), select "none" as the action. DO NOT check "Perform action with all infections". If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again.
  • When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.
***

Use Windows Explorer to remove these folders:
C:\WINDOWS\QW5keQAA\
C:\Program Files\WinFixer 2005\
C:\Program Files\ornu\

Then, move to this folder:
C:\WINDOWS\Downloaded Program Files\
See if you have a file that looks like this one:
UWFX5LP_0001_0803NetInstaller.exe

The digits may change. If you find it, remove it.
Close Windows Explorer when you are done.

***

Reboot back to normal mode.

***

Download L2mfix from one of these two locations:

http://www.atribune....oads/l2mfix.exe
http://www.downloads....org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

***

Post back to this topic with the Ewido log, a fresh HijackThis log and the L2M log.
  • 0

#3
Invisible Touch

Invisible Touch

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
for some reason i cant post all of the logs at once????


Logfile of HijackThis v1.99.1
Scan saved at 5:57:40 PM, on 8/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\America Online 9.0a\aoltray.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ed\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.limewire.com/clientpro?en
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [second] C:\Documents and Settings\Ed\Desktop\l2mfix\second.bat
O4 - HKLM\..\Run: [dnam] C:\Documents and Settings\Andy\d140113.a.Stub.EXE
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [vidctrl] C:\WINDOWS\system32\vidctrl\vidctrl.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0a\aoltray.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O15 - Trusted Zone: http://www.newgrounds.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Edited by Invisible Touch, 18 August 2005 - 03:58 PM.

  • 0

#4
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
The logs will be too large for one single post.

Post them in multiple posts then, I'll have a look.
  • 0

#5
Invisible Touch

Invisible Touch

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
L2MFIX find log 1.03c
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{3BC1383E-1395-9140-F109-225062265673}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"

**********************************************************************************
HKEY ROOT CLASSIDS:
**********************************************************************************
Files Found are not all bad files:
Locate .tmp files:
**********************************************************************************
Directory Listing of system files:
Volume in drive C is PRESARIO
Volume Serial Number is A0D3-AF1E

Directory of C:\WINDOWS\System32

08/18/2005 05:31 PM <DIR> ..
08/18/2005 05:31 PM <DIR> .
08/18/2005 03:23 PM <DIR> dllcache
07/21/2005 09:55 AM 401,408 r?gsvr32.exe
01/27/2005 08:18 PM <DIR> Microsoft
1 File(s) 401,408 bytes
4 Dir(s) 135,727,898,624 bytes free
  • 0

#6
Invisible Touch

Invisible Touch

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 5:31:32 PM, 8/18/2005
+ Report-Checksum: A93B065D

+ Scan result:

:mozilla.37:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Atdmt : Ignored
C:\Documents and Settings\Emma\Complete\AVI DivX MPEG to DVD Converter and Burne.zip/Setup.exe -> Worm.VB.an : Ignored
HKLM\SOFTWARE\Classes\CLSID\{A8BD9566-9895-4FA3-918D-A51D4CD15865} -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839} -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{16097036-894C-4C00-A61F-93CA0D49A70E} -> Spyware.TOPicks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{2BB15D36-43BE-4743-A3A0-3308F4B1A610} -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{2ED5AF98-9258-45BA-B79B-06625C92F662} -> Spyware.TOPicks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{41700749-A109-4254-AF13-BE54011E8783} -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{700DC0DD-F409-42E0-9DE5-21EE1A2BA9FD} -> Spyware.TOPicks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C91E8926-D4BE-4685-99F4-0D996B96BAC0} -> Spyware.P2PNetworking : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{FD42F6D3-7AB1-470C-979B-7996EDC99099} -> Spyware.TOPicks : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073} -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{F720B40F-3A38-4B22-B30D-DCF095D42498} -> Spyware.P2PNetworking : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Mvu -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Need2Find -> Spyware.Need2Find : Cleaned with backup
HKLM\SOFTWARE\Need2Find\bar -> Spyware.Need2Find : Cleaned with backup
HKLM\SOFTWARE\Need2Find\bar\Partner -> Spyware.Need2Find : Cleaned with backup
HKU\S-1-5-21-1266980298-1008762857-234771302-1014\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9} -> Spyware.BookedSpace : Cleaned with backup
HKU\S-1-5-21-1266980298-1008762857-234771302-1014\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} -> Spyware.MyWebSearch : Cleaned with backup
HKU\S-1-5-21-1266980298-1008762857-234771302-1014\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{016235BE-59D4-4CEB-ADD5-E2378282A1D9} -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-21-1266980298-1008762857-234771302-1014\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0} -> Spyware.RXToolbar : Cleaned with backup
HKU\S-1-5-21-1266980298-1008762857-234771302-1014\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Spyware.NewDotNet : Cleaned with backup
HKU\S-1-5-21-1266980298-1008762857-234771302-1014\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3} -> Spyware.Need2Find : Cleaned with backup
HKU\S-1-5-21-1266980298-1008762857-234771302-1014\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4D1C4E89-A32A-416B-BCDB-33B3EF3617D3} -> Spyware.Need2Find : Cleaned with backup
HKU\S-1-5-21-1266980298-1008762857-234771302-1014\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9EB320CE-BE1D-4304-A081-4B4665414BEF} -> Spyware.PurityScan : Cleaned with backup
HKU\S-1-5-21-1266980298-1008762857-234771302-1014\Software\Need2Find -> Spyware.Need2Find : Cleaned with backup
HKU\S-1-5-21-1266980298-1008762857-234771302-1014\Software\Need2Find\bar -> Spyware.Need2Find : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.147:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.158:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.159:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.173:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.175:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.180:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.182:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.214:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Epilot : Cleaned with backup
:mozilla.215:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Epilot : Cleaned with backup
:mozilla.216:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Epilot : Cleaned with backup
:mozilla.217:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Epilot : Cleaned with backup
:mozilla.218:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Epilot : Cleaned with backup
:mozilla.221:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup
:mozilla.223:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.249:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.250:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.251:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.252:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.253:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.259:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.260:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.261:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.267:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.268:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.271:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.272:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.273:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.274:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.275:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.298:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.299:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.300:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.324:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.325:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.337:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.338:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.339:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.347:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.354:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.356:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.358:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.373:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.379:C:\Documents and Settings\Ed\Application Data\Mozilla\Firefox\Profiles\lfl6nr8n.default\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Ed\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Ed\Cookies\[email protected][2].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Ed\Cookies\ed@targetnet[1].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Documents and Settings\Ed\Cookies\ed@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Ed\Local Settings\Temp\9569958_11240_3084_11988_63.41.tmp -> Spyware.EliteBar : Cleaned with backup
C:\Documents and Settings\Ed\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Ed\Local Settings\Temp\Cookies\ed@paypopup[1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Ed\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Ed\Local Settings\Temp\temp.exe -> Spyware.EliteBar : Cleaned with backup
C:\Documents and Settings\Ed\Local Settings\Temp\Temporary Internet Files\Content.IE5\C1QVGHQF\kw[1].exe -> Spyware.EliteBar : Cleaned with backup
C:\Documents and Settings\Ed\Local Settings\Temporary Internet Files\Content.IE5\U9C2YQQO\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Emma\Application Data\Mozilla\Firefox\Profiles\c0pbim7s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Emma\Application Data\Mozilla\Firefox\Profiles\c0pbim7s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Emma\Application Data\Mozilla\Firefox\Profiles\c0pbim7s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Emma\Application Data\Mozilla\Firefox\Profiles\c0pbim7s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Emma\Application Data\Mozilla\Firefox\Profiles\c0pbim7s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Emma\Application Data\Mozilla\Firefox\Profiles\c0pbim7s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Emma\Application Data\Mozilla\Firefox\Profiles\c0pbim7s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Emma\Application Data\Mozilla\Firefox\Profiles\c0pbim7s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Emma\Application Data\Mozilla\Firefox\Profiles\c0pbim7s.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Emma\Application Data\Mozilla\Firefox\Profiles\c0pbim7s.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Emma\Complete\ Adobe Photoshop CS2 v9.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\ IPSwitch Whatsup Professional 2005 SP1a.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\ Norpix Streampix 3.17.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\2Flyer Screensaver Builder Pro v7.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\3D Album Commercial Suite 3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\50 Cent - The Massacre 2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\602Print Pack v5.0.05.0805.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\7-Zip 4.26.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Absolute Video to Audio Converter v2.3.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\ACD Systems FotoSlate 4.0.22.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\ACDSee PowerPack 7.0.61.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Ace Video Workshop 1.4.31.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Acme Photo ScreenSaver Maker 1.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Acoustica 3.20.249.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Acoustica CDDVD Label Maker v2.17.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Acronis Disk Director Suite v9.0 Build 5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Active Key Logger 2.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Ad-aware Se Profesional V1.06 Retail.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Adobe Photoshop CS2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Adobe Premier Pro 7.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Adobe Premier PRO 7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Advanced Anti Keylogger v3.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Advanced Files Repair.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Advanced Registry Doctor Pro V5.3.6.15.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\AdwareX Eliminator 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Agama Web Buttons v2.53.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Ahead DVD Ripper 1.1.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Ahead NeroVision Express 3.1.0.11.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Akon - Trouble (2004).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Alias Maya 7.0 Retail Full.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Alias Maya Unlimited 7.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Alias Maya Unlimited v7.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\AliveGames Fishing Trip 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\All adobe products.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\All axialis software.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\All In One dBpowerAMP Music Converter.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Amadis DVD Ripper Professional v1.0.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Amazon DVD Shrinker v2.1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\American Pie 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\American Wedding.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Americas Army 2.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\AnyDVD 5.4.1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\AnyDVD v5.2.4.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\AnyDVD v5.4.1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Arles Image Web Page Creator v6.12.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\As-U-Type v3.1 - R E T A I L.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Ashampoo Burning Studio 5 v5.2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Ashampoo Burning Studio v5.2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Ashampoo WinOptimizer Platinum Suite 2 1.00.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\ASPMaker 4.1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Atani v2.8.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Audio Editor Gold Xmas Edition 7.0.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Audio Recorder Pro v3.12.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\AudioJack 1.42.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Aurora DVD Copy v1.3.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Aurora Mediaworkshop v2.4.15.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Auto FTP Manager 3.40.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\AutoUpdate Plus v3.00.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Av Voice Changer Diamond Edition 4.0.39.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Backstreet Boys - Never Gone.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Backup Made Simple 5.1.157.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Backup Made Simple v5.1.157.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Backup To CD-RW 5.1.86.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Bad CD Repair 1.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Bad CD Repair Pro 3.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Ball 7 Deluxe 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Ball 7 Deluxe v1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Bass Guitar Mode Maker v2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Batch Video Converter 1.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Batch Video Converter v1.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Batch Video Joiner 1.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Batch Video Joiner v1.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Batch WMV to AVI MPEG WMV VCD SVCD DVD C.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Becky Internet Mail v2.21.04.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\BeFaster 3.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Billy Corgan - The Future Embrace.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Bitvise WinSSHD v4.03.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Black white.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Blaze DVD Copy 3.5.9.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\BlindWrite 5.2.9.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\BluffTitler DX9 v2.04.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Boilsoft ASF Converter 2.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Boilsoft AVI MPEG RM WMV Joiner 4.81.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Boilsoft RM Converter 2.21.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Bow Wow - Wanted - 2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\BR PhotoArchiver 4.15.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Browser Hijack Recover(BHR) v2.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\BSPlayer Pro 1.32.820.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Bubble Wrap v1.0 ARM PPC.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\BurnerSoft Easy DVD Shrink 3.0.12.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\BVRP Ringtone Media Studio v1.0.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\BWMeter v2.3.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\BWMeter v2.34.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Call of Duty.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Cam Analyzer 3.2.B.011.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Cam Analyzer v3.2.B.011.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\CamUpload v1.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\CaptureWizPro 3.20.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\CD Bank Cataloguer v2.7.0.208.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\CD Roller 6.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\CD-Cover Editor v2.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Charles v2.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Chimera Virtual Desktop 1.3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Chimera Virtual Desktop v1.3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Church Contribution System v3.03a.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Clean Disk Security v7.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\CleanCenter 1.34.72.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Clock Tray Skins 1.77.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Clock Tray Skins v1.77.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Clone Killer 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\CloneDVD v2.8.4.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Closer 2004.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\CoffeeCup Google SiteMapper 3.04.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Coldplay - Live 2003.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Computer Power User - Sep 2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Coyote Groove Mechanic v2.5c.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\CpuIdle Extreme 7.0.4.14.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\CpuIdle Extreme v7.0.4.14.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Crackers Matrix.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Crazy Machines - New Challenges.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\CSI Miami.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Cursed.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DAP PLUS 7.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Dave Mirra Pro BMX.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Days Of Thunder.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DaySmart.v5.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DB-Weave v4.01.0239.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\dBpowerAMP Music Converter AIO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Dead to Rights.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Demo Builder 4.00.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Devour Xvid.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DevPlanner 2.0.756.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DevPlanner v2.0.756.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Diablo 2 EXtension.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Diablo 2 + Expansion.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Diablo 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DialItNow 1.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DialItNow v1.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Dire Straits - Money For.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Direct MIDI to MP3 Converter v1.2.0.30.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Discreet 3dmax Unplugged 2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DiskStateV281Build550.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DivXToDVD 1.99.19.30.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DJ Java Decompiler 3.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Dr. Hardware 2005 6.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DreamenStudio iESpa v1.21 build 393.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Dup-DVD 2.1.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DupehunterProCorporateEdition 260.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Duplicate File Detective v1.5.1.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DVD Copy Express v5.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DVD Cover Searcher Pro v2.2.5 Final.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DVDFab Platinum v2.9.3.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DVDInfo Pro 4.25.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DVDInfoPro 4.25.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\DVDReMake Pro v3.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\EarthTime v1.4.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\EarthView 3.30.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\EarthView V3.3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\EarthView v3.30.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Easy DVD to VCD Burner 2.0.48.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Easy File Sharing Web Server 3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Easy File Sharing Web Server v3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Easy Music CD Burner v3.0.24.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Easy Video to Audio Converter v1.2.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\EIQ MailAnalyzer 3.6.36.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\EIQ MailAnalyzer v3.6.36.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\ejay DJ Mix Station.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Electrasoft 32bit Service Monitor s9.80..zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Electrasoft Popup Ad Stopper v9.80.01 Final.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Eminem - Marshall Mathers.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Enterprise Threat Shield v3.00.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Error Doctor 2006 v1.0.0.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\eX-Sense Pro! v4.2.34 - UPD....zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\FairStars Audio Converter 1.45.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\FairStars Audio Converter 1.52.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\FairStars Audio Converter v1.5.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Family Guy The Movie.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Fantastic 4 (Game).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Fantastic Four.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\FarPoint Input Pro for Windows Forms v1..zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Fast Defrag Professional 2.25.96 SP2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Federation - Federation.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\FireGraphic v7.0.705.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\FireTuneUp v1.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\FirmTools Album Creator Pro 3.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\First Alert Service Monitor v9.80.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Flash Studio Pro 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Flash SWF to GIF AVI Converter v1.4.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Flash2Video 2.26.300.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Flash2Video v2.26.300.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\FlashFXP 3.2 1080.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Forte Agent v3.0.763.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Free Internet TV v4.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\FruityLoops 5.0.2c.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\FruityLoops 5.02c.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\FTP Now 2.6.21.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\FTP Now v2.6.21.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\FTP Voyager 12.2.0.0 Enterprise.zip/Setup.exe -> Worm.VB.an : Cl
  • 0

#7
Invisible Touch

Invisible Touch

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
C:\Documents and Settings\Emma\Complete\Trojan Remover 6.3.5 Retail.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Trojan Remover 6.4.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Trojan Remover v6.4.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Tunnel trance force & Russian Dream.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Twisted Metal 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\UEStudio 05.00.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Ulead MediaStudio Pro 7.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Ulead Photo Express 4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Ultra Remote Control v2.6.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\UltraCompare Professional v.3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\vBulletin 3.0.8 PHP.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Video Edit Magic 4.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\VinylMaster Pro 7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\VirtuaGirl 2.52.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Visual CertExam Suite 1.7.542.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Visual CertExam Suite v1.7.542.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\VoiceMX Studio v4.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\VSO DivXToDVD v1.99.12.27.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\VueScan Pro v8.2.30.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Vyapin Admin Report Kit for Exchange Server 3.21.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Vyapin Admin Report Kit for Internet Information Server v3.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Vyapin Document Import Kit SharePoint.20.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Warez P2P 2.85 .zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Wealth-Lab Developer 3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\WebEQ Developers Suite v3.7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\WeBuilder 2005 v6.2.0.55.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Willing Webcam v2.9.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Winamp 5.094 Final Pro + Full + Lite.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Windows 2000 with SP4 5 in1 Multiboot.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Windows Server 2003 10 in 1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Windows Vista Beta 1 Icons.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\WinDVD Platinum v7.0.B27.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\WinHex v12.35 SR-2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\WinRAR 3.50 Beta 5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Wolfenstein ET Patch.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Wolfenstein ET.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\WorldWide FTP 2.43.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Worms 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\WWW File Share Pro 3.20.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Xeru Image Converter 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Xeru Image Converter 1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\XingMP3 Encoder 1.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\XML Buddy Pro v2.0.73.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\XPlite Professional 1.5.0273.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\YASA VOB to MPEG Converter v3.2.36.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\YeoSoft Text to MP3 Speaker v5.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Ying Yang Twins - United State Of Alnt.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Yoga 2.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Your Uninstaller! 2005 5.0.0.117 Beta.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Zealot All Video to VCD SVCD DVD Creator.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\ZoneAlarm Software Security Suite.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Zoom Player v4.51 Professional.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Complete\Zoom Player VMW Professional 4.51.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Emma\Cookies\emma@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Emma\Cookies\emma@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Emma\Cookies\emma@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Emma\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Emma\Cookies\emma@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Emma\Cookies\emma@overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Emma\Cookies\[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Emma\Cookies\emma@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Emma\Cookies\[email protected][2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Emma\Local Settings\Temp\b.com -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Emma\Local Settings\Temp\Cookies\emma@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Emma\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Emma\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Emma\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Emma\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Emma\Local Settings\Temp\res31.tmp -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Emma\Local Settings\Temporary Internet Files\Content.IE5\QRKP896P\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Emma\Local Settings\Temporary Internet Files\Content.IE5\SJ2L052V\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Emma\Local Settings\Temporary Internet Files\Content.IE5\SJ2L052V\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Emma\Local Settings\Temporary Internet Files\Content.IE5\YDOT8R01\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Emma\Local Settings\Temporary Internet Files\Content.IE5\YDOT8R01\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Emma\Local Settings\Temporary Internet Files\Content.IE5\YPMRAP4V\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Emma\Local Settings\Temporary Internet Files\Content.IE5\YPMRAP4V\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Emma\Local Settings\Temporary Internet Files\Content.IE5\YPMRAP4V\AppWrap[3].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\01KLMNIP\!update-2274[1].0000 -> Spyware.MediaTickets : Cleaned with backup
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\H71Q0Q22\!update-2214[1].0000 -> TrojanDownloader.PurityScan.y : Cleaned with backup
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\M9IFUTCR\!update-2204[1].0000 -> TrojanDownloader.PurityScan.y : Cleaned with backup
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\M9IFUTCR\!update-2224[1].0000 -> TrojanDownloader.PurityScan.y : Cleaned with backup
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\M9IFUTCR\!update-2234[1].0000 -> TrojanDownloader.PurityScan.y : Cleaned with backup
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\M9IFUTCR\!update-2244[1].0000 -> TrojanDownloader.PurityScan.y : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\0643E0D2-84D3-4F6F-8B3B-CBC4A6\7B8ACFAA-792E-4663-A306-079DB5 -> Spyware.NewDotNet : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\62901AA9-43CD-45F0-9E1E-D9BE5F\061B24CC-FDCD-4254-B6A2-B66E0B -> TrojanDownloader.Qoologic.aa : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\62901AA9-43CD-45F0-9E1E-D9BE5F\81D1DB57-E2EE-4AEC-9EC2-3C6B66 -> TrojanDownloader.Qoologic.aa : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\62901AA9-43CD-45F0-9E1E-D9BE5F\BF682F49-5FF8-4BB4-86EB-2D5772 -> TrojanDownloader.Qoologic.aa : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\91BE8B87-6E97-4754-9948-F8ACD4\CAAAB66A-89CA-405C-8AF7-B64E1B -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\E837374E-33D5-4470-A8AC-FFCA00\B277706E-DF81-4375-9D54-F85BE1 -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Program Files\Need2Find -> Spyware.Need2Find : Cleaned with backup
C:\Program Files\Need2Find\bar -> Spyware.Need2Find : Cleaned with backup
C:\Program Files\Need2Find\bar\History -> Spyware.Need2Find : Cleaned with backup
C:\Program Files\Need2Find\bar\History\search -> Spyware.Need2Find : Cleaned with backup
C:\Program Files\Need2Find\bar\Settings -> Spyware.Need2Find : Cleaned with backup
C:\Program Files\Uninstall Need2Find Bar.dll -> Spyware.MySearch : Cleaned with backup
C:\Program Files\winupdates\a.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\WINDOWS\ru.exe -> Spyware.PurityScan : Cleaned with backup
C:\WINDOWS\system\UpdInst.exe -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\cjmrepl.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\cnxqccm.exe -> TrojanDownloader.Qoologic.aa : Cleaned with backup
C:\WINDOWS\system32\conres.cpl -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\dEdim.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dgdiagn.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dkutil.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\fjdrclnr.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\guard.tmp -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\hI23msp.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\hzd.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ikwphbk.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\jаvaw.exe -> Spyware.PurityScan : Cleaned with backup
C:\WINDOWS\system32\kkduk.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mcc70u.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mcxml4.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mdrmsg.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mjhtml.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mqrapi.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mvls31.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mwpatcha.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\nqtman.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\pafmgr.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\pfofmap.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\pinppagn.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\rqgapi.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\rrvpmsg.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\sdimeng.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\sfdll.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\skytown.exe -> TrojanSpy.VB.eh : Cleaned with backup
C:\WINDOWS\system32\spmpsnap.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\swcfiles.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\tyext.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\udbui.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\WIVADVE.DLL -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ydykn.dll -> Spyware.PurityScan : Cleaned with backup
C:\WINDOWS\system32\znpfldr.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\Temp\!update.exe -> TrojanDownloader.PurityScan.y : Cleaned with backup
C:\WINDOWS\Temp\b.com -> TrojanDropper.Agent.pb : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Temp\Cookies\andy@paypopup[1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Temp\Cookies\ed@paypopup[1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\WINDOWS\Temp\Cookies\ed@revenue[1].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\WINDOWS\Temp\Cookies\ed@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Temp\Cookies\emma@paypopup[1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup


::Report End


not all of the ewido scan fit in one post
  • 0

#8
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!



EDIT:
As there has been no reply from the original poster for more than two weeks this topic is now closed.

If you are the original poster and still need assistance, please send me a PM.

Edited by g2i2r4, 10 September 2005 - 11:34 AM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP